Описание
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:odoo:odoo:11.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:11.0:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 58%
0.00359
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 6.5
debian
больше 6 лет назад
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo ...
github
больше 3 лет назад
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.
EPSS
Процентиль: 58%
0.00359
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-732